Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-21575 — Atlassian Sourcetree Remote Code Execution Vulnerability

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, wit…

sourcetree | Remote | Authentication
Jul 21, 2026 Jul 24, 2026
Jul 21, 2026
Jul 24, 2026
7.8 HIGH
CVE-2026-16493 — Ansible-core: argument injection in ansible-galaxy collection install via git clone (inco…

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator be…

Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.8 MEDIUM
CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow

In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

openj9 | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
5.7 MEDIUM
CVE-2026-16243 — Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compa…

In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

omr | Remote | Memory Corruption
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
9.8 CRITICAL
CVE-2026-47410 — praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowin…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcod…

praisonai | Remote | Cryptography
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47409 — praisonai-platform: Any workspace member can remove any other member (including the owner…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.5 MEDIUM
CVE-2026-47408 — praisonai-platform: list_issue_activity returns activity log for any issue regardless of …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issu…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
9.4 CRITICAL
CVE-2026-47407 — PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and pr…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47406 — praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-47405 — PraisonAI Platform missing role checks let any workspace member become owner and take ove…

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege wo…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
8.8 HIGH
CVE-2026-47399 — PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global …

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that a…

praisonai | Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-47398 — PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_ge…

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.p…

praisonai | Remote | Supply Chain
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
7.1 HIGH
CVE-2026-47397 — PraisonAI has an Arbitrary File Write in Python API

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path…

praisonai | Remote | Path Traversal
Jul 21, 2026 Jul 23, 2026
Jul 21, 2026
Jul 23, 2026
7.5 HIGH
CVE-2026-44907 — React Server DOM Denial of Service Vulnerability

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages:…

| Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-24232 — NVIDIA Transformers4Rec Improper Deserialization Vulnerability

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data…

| Injection
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
4.3 MEDIUM
CVE-2026-16454 — Privilege Escalation in Eclipse hawkBit DDI allows Tenant-Isolated Firmware Exfiltration

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allo…

Remote | Authorization
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
6.5 MEDIUM
CVE-2026-16451 — zsadmin2025 ZS-Admin com.zs.file.controller.SysFileController upload unrestricted upload

A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.z…

zs-admin | Remote | Misconfiguration
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
8.6 HIGH
CVE-2026-15829 — SQL Injection and Security Boundary Bypass in googleapis/mcp-toolbox

A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-…

mcp_toolbox_for_databases | Remote | Injection
Jul 21, 2026 Jul 22, 2026
Jul 21, 2026
Jul 22, 2026
7.3 HIGH
CVE-2026-15793 — Git source checkout from a bundle file could lead to command injection

BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command in…

buildkit | Remote | Misconfiguration
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
6.3 MEDIUM
CVE-2026-15792 — Possible panic when incorrect parameters sent from frontend

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

buildkit | Remote | Denial of Service
Jul 21, 2026 Jul 21, 2026
Jul 21, 2026
Jul 21, 2026
Showing 20 of 9583 Results